Board and management
Oversight and accountability.
The SC's Guidelines on Technology Risk Management replaced the old cyber risk guidelines in 2024 and added near-miss reporting, pre-deployment security assessment and penetration testing of critical systems. We review your compliance and evidence against them.
A compliance review of a capital market entity's technology risk governance, processes and evidence against the SC guidelines. It reviews whether required testing happens and is evidenced; it does not perform the testing itself.
The guidelines apply to capital market entities including fund managers, brokers, platform operators and trustees. The 2024 revision requires near-miss reporting, a cyber security assessment before deploying a system, penetration testing before deploying new critical systems, and allows the SC to appoint an independent party to review compliance. Many entities have policies but not the evidence.
Oversight and accountability.
Pre-deployment assessments and testing gates.
Oversight of providers.
Identification and reporting to the SC.
Ethical use guidance.
Records an SC-appointed reviewer would request.
Evidence in place.
The 2024 revision, not the old cyber rules.
Release processes that comply.
Independent view.
Compliance review, no intrusive testing.
Entity and systems.
Policies and records.
Change, incident and third-party processes.
Against the guidelines.
Findings and plan.
Findings by risk.
Requirement by requirement.
Draft or review.
Owners and dates.
Position for directors.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
The SC Guidelines on Technology Risk Management, issued 1 August 2023 and revised 19 August 2024, which replaced the 2016 cyber risk guidelines.
No. We review whether required testing happens and is evidenced. Testing is performed by licensed providers.
An event that could have caused an incident but did not. The guidelines require reporting them to the SC.
No. The SC appoints its own reviewer. This prepares you for one.
Typically three to six weeks.
Tell us your entity type and key systems. We will scope and quote.